🇦🇺
2000cn.com.au
2026-09-07 23:06:28
(7 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇷
solution.it
2026-09-07 22:46:47
(26 minutes ago)
[Tue Sep 08 00:46:47.274733 2026] [php7:error] [pid 4504:tid 4504] [client 79.127.216.70:43371] scri ...
show more
[Tue Sep 08 00:46:47.274733 2026] [php7:error] [pid 4504:tid 4504] [client 79.127.216.70:43371] script '/var/www/html/blog.solution.it/info.php' not found or unable to stat
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 22:38:07
(35 minutes ago)
(mod_security) mod_security (id:210730) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com ...
show more
(mod_security) mod_security (id:210730) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 18:38:03.065338 2026] [security2:error] [pid 3773:tid 3773] [client 79.127.216.70:48010] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||internetnameregistration.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "internetnameregistration.com"] [uri "/db.sql"] [unique_id "ap88yxy0wE-5WzwZjicDHgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 22:19:24
(54 minutes ago)
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 18:19:17.787112 2026] [security2:error] [pid 32345:tid 32345] [client 79.127.216.70:18122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.virtualmediamasters.net"] [uri "/wp-config.php.bak"] [unique_id "ap84ZQpN7O7dxefxaFxnOgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 21:58:01
(1 hour ago)
79.127.216.70 - - [08/Sep/2026:05:58:01 +0800] "GET /.env.swp HTTP/1.1" 200 30686 "-" "Mozilla/5.0 ( ...
show more
79.127.216.70 - - [08/Sep/2026:05:58:01 +0800] "GET /.env.swp HTTP/1.1" 200 30686 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:42:53
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:42:48.848984 2026] [security2:error] [pid 26859:tid 26859] [client 79.127.216.70:24970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mardensmith.com"] [uri "/wp-config.php.save"] [unique_id "ap8v2A8jjTDJcb8ahGiW6wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 21:25:02
(1 hour ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:24:05
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:23:57.811835 2026] [security2:error] [pid 27597:tid 27597] [client 79.127.216.70:31421] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pleaseaddbacon.com"] [uri "/wp-config.php.swp"] [unique_id "ap8rbW2yMY0tv8OwEfDr7wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:02:44
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:02:37.854270 2026] [security2:error] [pid 27673:tid 27673] [client 79.127.216.70:32746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modalguitarist.com"] [uri "/wp-config.php.orig"] [unique_id "ap8mbQoY-eklRBRd6RGLUwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 20:33:49
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:33:05
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:32:58.157436 2026] [security2:error] [pid 17272:tid 17272] [client 79.127.216.70:54265] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rachelfia.fiasdesigns.com"] [uri "/wp-config.php.swp"] [unique_id "ap8fenfLwm9yCNYNHpQmEgAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
VanKoh
2026-09-07 20:25:58
(2 hours ago)
79.127.216.70 - - [07/Sep/2026:14:25:55 -0600] "GET /wp-config.php.txt HTTP/1.1" 404 58296 "-" "Mozi ...
show more
79.127.216.70 - - [07/Sep/2026:14:25:55 -0600] "GET /wp-config.php.txt HTTP/1.1" 404 58296 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
79.127.216.70 - - [07/Sep/2026:14:25:56 -0600] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
79.127.216.70 - - [07/Sep/2026:14:25:56 -0600] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:12:47
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:12:39.754122 2026] [security2:error] [pid 22446:tid 22446] [client 79.127.216.70:26381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lesdaniels.com"] [uri "/wp-config.php.orig"] [unique_id "ap8at63AQv6bwtmc_lGqngAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-07 20:05:03
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:56:44
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 79.127.216.70 (unn-79-127-216-70.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:56:39.831744 2026] [security2:error] [pid 20681:tid 20681] [client 79.127.216.70:48259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fgrotary.org"] [uri "/wp-config.php~"] [unique_id "ap8W9z2fZGaEh2sgwnBA1AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack